Description
Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive normalization. Attackers can embed a newline in a nested model_type value within a malicious model's config.json to terminate the generated import statement and execute arbitrary Python code via exec() in unsloth_compile_transformers(), achieving remote code execution as the loading user when the model is loaded for training or inference.
Published: 2026-09-28
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Unsloth Zoo versions prior to 2026.8.14, as included in Unsloth releases 2025.9.9 through 2026.8.19, contain a code injection flaw. The get_transformers_model_type() function collects model_type values from nested model configurations without restricting the character set, allowing an attacker to place a newline in a nested model_type. The newline ends the generated import statement and enables arbitrary Python code to be executed by exec() during the compile step, giving remote code execution as the user that loads the model for training or inference.

Affected Systems

Products affected are unslothai Unsloht and unslothai Unsloht Zoo. Version ranges impacted include Unsloht Zoo 2025.9.9 up through 2026.8.13 (inclusive) and Unsloht 2025.9.9 through 2026.8.19. Any instance of these releases that loads models from untrusted sources is vulnerable.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalogue. An attacker who can supply a malicious config.json to the model‑loading API can trigger remote code execution. The likely attack vector is via a compromised model file stored in a public or unprotected repository and then loaded by a system using Unsloht or Unsloht Zoo. Because the flaw is in the compile path, environments that auto‑load models for inference or training without additional validation are exposed.

Generated by OpenCVE AI on September 28, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest unsloth and unsloth‑zoo releases that include the vendor fix.
  • If an immediate upgrade is not possible, restrict model loading to trusted sources and preprocess config.json files to remove any newline characters from the model_type field or validate the model_type string against an allowlist of alphanumeric characters.
  • Run the model‑loading process under the least‑privilege user account to minimize potential impact of any successful remote code execution.

Generated by OpenCVE AI on September 28, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Unslothai
Unslothai unsloth
Unslothai unsloth-zoo
Vendors & Products Unslothai
Unslothai unsloth
Unslothai unsloth-zoo

Mon, 28 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive normalization. Attackers can embed a newline in a nested model_type value within a malicious model's config.json to terminate the generated import statement and execute arbitrary Python code via exec() in unsloth_compile_transformers(), achieving remote code execution as the loading user when the model is loaded for training or inference.
Title Unsloth Zoo Code Injection via model_type in config.json
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Unslothai Unsloth Unsloth-zoo
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T15:09:41.524Z

Reserved: 2026-09-17T18:41:40.757Z

Link: CVE-2026-93348

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:17.643

Modified: 2026-09-28T16:17:17.643

Link: CVE-2026-93348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:42:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')